Skip to content

[Security] Bump ActiveMQ from 5.14.5 to 5.19.2 (fixes CVE-2023-46604)#37944

Merged
Abacn merged 1 commit intoapache:masterfrom
bvolpato:bvolpato/bump-activemq-5.19.2
Mar 25, 2026
Merged

[Security] Bump ActiveMQ from 5.14.5 to 5.19.2 (fixes CVE-2023-46604)#37944
Abacn merged 1 commit intoapache:masterfrom
bvolpato:bvolpato/bump-activemq-5.19.2

Conversation

@bvolpato
Copy link
Contributor

Summary

Upgrades ActiveMQ from 5.14.5 to 5.19.2 to remediate critical security vulnerabilities. ActiveMQ is used exclusively as a test dependency in Beam (embedded broker for JMS, MQTT, and AMQP IO connector tests).

CVEs Fixed

CVE CVSS Severity Description
CVE-2023-46604 10.0 🔴 Critical Remote Code Execution via ClassInfo manipulation in OpenWire protocol. Actively exploited in the wild by ransomware.
CVE-2022-41678 8.8 🔴 High RCE via Jolokia and REST API

Changes Required for Compatibility

  1. JMS spec upgrade (JMS IO): geronimo-jms_1.1_spec:1.1.1geronimo-jms_2.0_spec:1.0-alpha-2
    • ActiveMQ 5.19.x uses JMS 2.0 API internally (setJMSDeliveryTime). JMS 2.0 is fully backward-compatible with JMS 1.1 — only adds new methods.
  2. MockNonSerializableConnectionFactory (JMS IO test): Added JMS 2.0 createContext() stubs.
  3. proton-j exclusion (AMQP IO): Excluded transitive proton-j:0.34.1 from activemq-amqp to avoid conflict with the directly declared proton-j:0.16.0.

Testing

All three affected test modules pass locally:

  • :sdks:java:io:jms:test (54 tests)
  • :sdks:java:io:mqtt:test
  • :sdks:java:io:amqp:test

Fixes #37943


Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:

  • Mention the appropriate issue in your description (for example: addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, comment fixes #<ISSUE NUMBER> instead.
  • Update CHANGES.md with noteworthy changes.
  • If this contribution is large, please file an Apache Individual Contributor License Agreement.

See the Contributor Guide for more tips on how to make review process smoother.

To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md

GitHub Actions Tests Status (on master branch)

Build python source distribution and wheels
Python tests
Java tests
Go tests

See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.

Fixes CVE-2023-46604 (CVSS 10.0, RCE via OpenWire protocol) and
CVE-2022-41678 (CVSS 8.8, RCE via Jolokia and REST API).

ActiveMQ is used exclusively as a test dependency in Beam (embedded
broker for JMS, MQTT, and AMQP IO connector tests).

Changes required for compatibility:
- Upgrade JMS spec from 1.1 to 2.0 (geronimo-jms) for JMS IO, since
  ActiveMQ 5.19.x uses JMS 2.0 API (setJMSDeliveryTime).
- Add JMS 2.0 createContext() stubs to MockNonSerializableConnectionFactory.
- Exclude transitive proton-j from activemq-amqp in AMQP IO to avoid
  conflict with the directly declared proton-j:0.16.0.

All three affected test modules pass: JMS IO, MQTT IO, AMQP IO.

Fixes apache#37943
@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the project's security by upgrading the ActiveMQ test dependency to a version that remediates critical vulnerabilities. The upgrade necessitated minor compatibility adjustments in related modules, primarily involving an update to the JMS specification and resolution of a transitive dependency conflict.

Highlights

  • ActiveMQ Upgrade for Security: Upgraded ActiveMQ from version 5.14.5 to 5.19.2 to address critical security vulnerabilities, including CVE-2023-46604 (CVSS 10.0) and CVE-2022-41678 (CVSS 8.8), which were actively exploited.
  • JMS Specification Update: Updated the JMS specification dependency from geronimo-jms_1.1_spec:1.1.1 to geronimo-jms_2.0_spec:1.0-alpha-2 to ensure compatibility with the new ActiveMQ version, noting JMS 2.0's backward compatibility.
  • Mock Connection Factory Adjustments: Modified MockNonSerializableConnectionFactory in JMS IO tests to include createContext() stubs, aligning with JMS 2.0 API requirements.
  • AMQP Dependency Exclusion: Added an exclusion for proton-j:0.34.1 from the activemq-amqp dependency in the AMQP IO module to prevent conflicts with an existing proton-j:0.16.0 declaration.

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@github-actions
Copy link
Contributor

Assigning reviewers:

R: @Abacn for label java.
R: @Abacn for label build.

Note: If you would like to opt out of this review, comment assign to next reviewer.

Available commands:

  • stop reviewer notifications - opt out of the automated review tooling
  • remind me after tests pass - tag the comment author after tests pass
  • waiting on author - shift the attention set back to the author (any comment or push by the author will return the attention set to the reviewers)

The PR bot will only process comments in the main thread (not review comments).

Copy link
Contributor

@Abacn Abacn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@Abacn Abacn merged commit 3aad50b into apache:master Mar 25, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] Upgrade ActiveMQ from 5.14.5 to 5.19.2 to fix CVE-2023-46604 and other vulnerabilities

2 participants